{
  "family": "upatre",
  "sample_count": 4200,
  "category": "downloader",
  "description": "Upatre is a Windows downloader trojan. As documented by Malpedia (Fraunhofer FKIE), it was first discovered in 2013 and has been widely updated since. Its primary role is to deliver further malware to victims: Upatre was a prolific delivery mechanism for the Gameover P2P (Gameover Zeus) banking trojan in 2013-2014, and later for the Dyre banking trojan in 2015. As a small first-stage downloader, it is typically distributed via spam email attachments and then retrieves and runs a larger second-stage payload.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "upatre downloader",
    "waski"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Upatre?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Upatre is a Windows downloader trojan first discovered in 2013. According to Malpedia, its primary purpose is to deliver further malware to infected systems, acting as a first-stage loader for larger threats."
      }
    },
    {
      "@type": "Question",
      "name": "What malware did Upatre deliver?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Per Malpedia, Upatre was a prolific delivery mechanism for the Gameover P2P (Gameover Zeus) banking trojan in 2013-2014, and later delivered the Dyre banking trojan in 2015."
      }
    },
    {
      "@type": "Question",
      "name": "How does a downloader like Upatre work?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Upatre is a small first-stage downloader. Once it runs on a victim's system, its job is to retrieve and execute a larger second-stage payload, which is the malware the attackers actually want to deploy. Malpedia notes Upatre has been widely updated over time."
      }
    },
    {
      "@type": "Question",
      "name": "Is Upatre still active?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Upatre was most prominent during 2013-2015 as a loader for Gameover Zeus and Dyre. Malpedia documents it as having been widely updated since its 2013 discovery; its activity is most strongly associated with that mid-2010s period."
      }
    }
  ],
  "faq_count": 4,
  "mitre_attack": [
    "T1566.001",
    "T1105",
    "T1071.001",
    "T1204.002"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-10",
  "sources": [
    {
      "name": "Malpedia (Fraunhofer FKIE): Upatre (win.upatre)",
      "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.upatre"
    }
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}